[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

250770

 
 

909

 
 

196157

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

ALAS2-2022-1764 --- expat

ID: oval:org.secpod.oval:def:1700869Date: (C)2022-03-11   (M)2024-04-25
Class: PATCHFamily: unix




A flaw was found in expat. Passing malformed 2- and 3-byte UTF-8 sequences to the XML processing application on top of expat can lead to arbitrary code execution. This issue is dependent on how invalid UTF-8 is handled inside the XML processor. A flaw was found in expat. Passing one or more namespace separator characters in the xmlns[:prefix] attribute values made expat send malformed tag names to the XML processor on top of expat. This issue causes arbitrary code execution depending on how unexpected cases are handled inside the XML processor

Platform:
Amazon Linux 2
Product:
expat
Reference:
ALAS2-2022-1764
CVE-2022-25235
CVE-2022-25236
CVE    2
CVE-2022-25235
CVE-2022-25236

© SecPod Technologies